
Hiring someone is a process that all HR teams go through and know very well. You’re welcoming a future team member who will have access to your clients, your data, and sometimes even your reputation, all based on the strength of a CV and a good interview. Background screening is how employers turn the process into an informed decision.
But the hiring legislation aren’t the same everywhere. What’s routine in the US can put you in front of a data protection regulator in Romania. What’s legally required in the UK might be optional across the Atlantic. If you hire across borders (and more HR teams do every year), one screening policy copied and pasted into every country is can create some difficult situations.
This FAQ answers the questions we hear most from HR teams, compliance officers, and hiring managers, with the specifics for Romania, the UK, and the US laid out side by side.
One caveat before we start: this is general guidance, not legal advice. Rules shift and local detail matters, so treat it as a solid starting point for a conversation with your screening partner or counsel.
Here is the AI podcast if you want to listen to it:
1. What is background screening?
Background screening is the structured process of verifying that a candidate is who they say they are, and that the claims on their CV hold up. In practice that usually means checking identity, employment history, education and qualifications, professional references, and, where the role and the law allow, criminal records. Some positions add credit checks, professional licence verification, or sanctions and media screening.
The point isn’t to catch candidates. It’s to confirm the facts so they are qualified for the role and they can be well integrated in the team. A finance hire who inflated a qualification, a driver with an undisclosed record, a caregiver who isn’t cleared to work with vulnerable people. Those are the risks screening surfaces early, while you can still make a calm decision instead of a crisis one.
Worth saying plainly: screening verifies information, it doesn’t dig for dirt. Good screening is narrow, relevant to the job, and proportionate. Everything below flows from that one idea.
2. Is background screening common?
Short answer: yes, and it’s growing in all three markets, though the maturity differs.
In the US, pre-employment screening is close to standard, especially for roles touching money, data, vehicles, or vulnerable people. In the UK, some checks aren’t just common but legally mandatory (every employer has to confirm a new hire’s right to work, with no exceptions). In Romania, candidate screening has grown steadily as employers in IT, BPO, banking, and healthcare have become increasingly aware of the risks of resume fraud and the real costs of a bad hire. It’s now a part of a recruitment process that is well organized rather than an unusual one.
What’s influencing it? Remote hiring made backgrounds easier to fake and harder to verify. CV fraud is up. And in regulated sectors, supervisors expect employers to know exactly who they’re hiring. Screening has quietly moved from “nice to have” to “part of doing this properly.”
3. What information can employers legally consider?
Across all three countries the safe zone is roughly the same: information that’s relevant and proportionate to the specific job. Identity, work history, education, references, and role-relevant qualifications are fair game more or less everywhere. The differences show up at the edges, criminal records, credit, health, and social media.
| Check type | Romania | UK | US |
| Identity / eligibility | ID verification, standard | Right to work check mandatory for all hires | Form I-9 mandatory; identity via screening provider |
| Employment history | Yes, proportionate | Yes, proportionate | Yes, common (often a 7-year window) |
| Education / qualifications | Yes, with candidate cooperation | Yes | Yes |
| Criminal record | Only where a law requires it for the role | Via DBS, by role eligibility (see Q5) | Yes, but FCRA, EEOC and ban-the-box rules apply |
| Credit history | Limited, must be justified | Limited, role-specific (e.g. finance) | Permitted with FCRA steps; some states restrict |
| Social media | Public info only, high caution | Public info only, high caution | Public info only, discrimination risk |
Proportionality is the test in Europe; job-relatedness and anti-discrimination rules are the test in the US. One of the most common mistakes employers make is collecting data “just in case,” without a clear, specific purpose.
4. How do data protection and background check laws impact screening?
This is where the three jurisdictions genuinely diverge.
In Romania and the UK, screening sits under data protection law: the EU GDPR plus Law 190/2018 in Romania, and the UK GDPR plus the Data Protection Act 2018 in Britain. Both expect you to identify a valid legal basis for processing someone’s data before you start, and to be transparent about it through a privacy notice.
Here’s a common misconception: “you just need the candidate’s consent.” In an employment context, consent is mandatory but, because the power imbalance between an employer and an applicant makes it hard to argue the consent was truly free (say no, risk the job). Regulators like the ICO expect the real legal basis to be legitimate interest, a legal obligation, or necessity for entering the contract, with consent in a supporting role.
Now, let’s look at the part that often causes confusion. In both Romania and the UK, employers, and screening providers like us, must obtain signed, informed consent from candidates. This consent clearly outlines exactly what will be checked, and no background verification can proceed without it. That’s correct and necessary. The nuance is what that document does. It authorizes the check and evidences transparency; however, it is not, by itself, what makes the data processing lawful. You need a proper legal basis behind it, and for criminal records especially, consent is never enough on its own (more in Q5).
The US runs on a different logic entirely. No GDPR. The key federal law is the Fair Credit Reporting Act (FCRA), and if you use a third-party screening company (a “consumer reporting agency”), you must give the candidate a standalone written disclosure and get their written authorization before running the check. Here, as well, written permission it’s mandatory. If you skip this step then you will be exposed to litigation.
| Jurisdiction | Main law + regulator | Signed consent? | Primary legal basis |
| Romania | EU GDPR + Law 190/2018; ANSPDCP | Yes, informed and written (in practice) | Legitimate interest / legal obligation / contract |
| UK | UK GDPR + Data Protection Act 2018; ICO | Yes, informed written consent is standard | Art. 6 basis + DPA condition; not consent alone for criminal data |
| US | FCRA (federal) + state law; FTC/CFPB, EEOC | Yes, written authorization legally required (via a CRA) | Statutory compliance (FCRA) + job-relatedness |
5. Can employers request criminal records?
Yes, but this is the most tightly controlled check in every one of these countries.
Romania. You can only require or process a criminal record (the cazier judiciar) where a specific law obliges it for the role. Think security staff, professional drivers, lawyers and notaries, certain medical roles, people working with children. For most ordinary jobs, demanding a record without that legal footing is itself a GDPR risk, and companies have been warned they can be fined for it. Conviction data is treated as especially sensitive under Article 10 of the GDPR. A workaround in this situations is to ask the candidate to present a valid certificate and record only the outcome (clear or not), rather than keeping a copy.
UK. Criminal record checks run through the Disclosure and Barring Service (DBS), and access depends on the role. A Basic check (unspent convictions only) is available for any role. Standard and Enhanced checks are restricted to roles listed under the Exceptions Order to the Rehabilitation of Offenders Act 1974, typically work with children or vulnerable adults, or regulated professions. You cannot run an Enhanced check on a general office hire. And most “spent” convictions can’t be held against a candidate unless the role is exempt. The ICO specifically warns against checking “just in case.”
US. You can obtain criminal history, but there are two extra steps that are applyed. First, EEOC guidance expects an individualized assessment rather than a blanket “any record, no job” rule: you weigh the nature of the offense, how long ago it was, and how it relates to the job. Second, ban-the-box (or “fair chance”) laws in most states and many cities restrict when you can even ask, often not until after a conditional offer. Arrest-only records and older items may be off-limits or time-limited under the FCRA and state rules.
| Jurisdiction | Can you check criminal records? | The key constraint |
| Romania | Only where a law requires it for the role | Article 10 GDPR; fines for unjustified requests |
| UK | Yes, via DBS, by role eligibility | Exceptions Order + Rehabilitation of Offenders Act |
| US | Yes | EEOC individualized assessment + ban-the-box timing |
6. Can employers inquire about a candidate’s social media presence?
You can look at what’s genuinely public. Whether you should, and what you’re allowed to do with it, is the harder question.
Regardless of the specific legal label used in each country, the underlying risk is essentially the same: social media exposes exactly the information you’re not allowed to base a hiring decision on. Age, religion, ethnicity, health, political views, pregnancy, sexual orientation. Once this information has been seen, it cannot be “unseen,” and if a rejected candidate suspects that these factors influenced the decision, the employer may face legal and reputational challenges.
In Romania and the UK, the GDPR principles of relevance and data minimisation apply to social media just like any other source, and a casual scroll through someone’s private life fails the proportionality test fast. In the US, the exposure is mainly discrimination law, plus a patchwork of state rules, some of which protect lawful off-duty conduct or bar employers from demanding social media passwords.
If you do it at all: keep it narrow, document why it’s relevant to the role, look only at professional or clearly public content, and tell the candidate you’re doing it. It is recommended to make job-relevant checks.
7. How far back can employers check an applicant’s employment history?
There’s not a standard recommended number, and it depends a lot on the role that you are hiring for.
In Romania and the UK, there’s no fixed statutory limit on how far back you can verify employment history itself. The governing principle is proportionality. Three to seven years covers most roles; reaching back two decades for a junior position is hard to justify.
The US is more prescriptive in places. The FCRA and various state laws impose lookback limits on certain reportable items (the well-known “seven-year rule” for some information, though higher-salary roles and certain record types are treated differently, and states vary). Verifying employment history is usually driven by relevance, but the reporting of adverse items is where the clocks start ticking.
A useful rule for all three contexts is to align the depth of the background check with the seniority level and risk associated with the role. For example, a Chief Financial Officer and a temporary warehouse worker do not require the same level of scrutiny, and treating them as if they do is neither efficient nor legally defensible.
8. Can employers verify a candidate’s educational background?
Yes, and honestly, you probably should. Qualification fraud is one of the most common forms of CV embellishment, from inflated grades to invented degrees and certificates.
Verification usually means going direct to the issuing institution, or using a screening partner that does. In all three countries this is legitimate and expected, provided you have the candidate’s cooperation and you handle the data properly. For international qualifications (increasingly normal with cross-border hiring), you may need credential evaluation or apostille steps, which take longer, so build that into your timeline.
One thing that we recommend is to verify the qualification that actually matters for the role. Confirming a required professional certification is proportionate.
9. Are there roles that require stricter screening?
Definitely. Some sectors carry legal or regulatory screening duties well beyond the norm, and the list is broadly similar across the three countries even where the specific rules differ. Expect heightened requirements for roles in:
- Finance and banking, where fit-and-proper and integrity checks are standard and regulators expect them.
- Healthcare, where patient safety and, in the US, exclusion-list checks come into play.
- Education and childcare, where working with minors triggers the strictest criminal and barring checks (the UK’s Enhanced DBS with barred lists is the clearest example).
- Security, transport, and safety-critical roles, where a clean record and specific certifications are often legally required.
- Public sector and roles needing security clearance.
In the UK, whether you can run a Standard or Enhanced check at all is decided by the Exceptions Order. In Romania, professional statutes dictate when a cazier is required. In the US, sector rules (financial services, healthcare) stack on top of the FCRA and EEOC baseline.
Also we will like to add that for lower-risk roles, avoid the temptation to conduct more screening than is necessary for the role. Applying a heavy, intrusive process to a job that doesn’t warrant it is a compliance risk in Europe and a discrimination risk in the US. And consistency counts, screen everyone applying for the same position the same way.
10. What should employers communicate to candidates about screening?
Communication is very important for transparency because it’s a legal requirement in all three places, and it’s where trust is build or lost in the process.
The recommendation is to tell candidates what checks you’ll run, why (the purpose and legal basis), what data you’ll collect, how long you’ll keep it, and what rights they have. In Romania and the UK, that comes through a privacy notice and, in practice, the signed consent document. In the US, the FCRA requires a standalone written disclosure and authorization before the check, and if results might lead you to reject someone, a specific two-step adverse action process: a pre-adverse notice (with a copy of the report, a summary of the candidate’s rights, and time to respond), followed by a final notice.
Two key practices distinguish employers who handle background screening effectively from those who end up facing complaints:
- Give candidates a chance to explain. If something questionable surfaces (a mistaken-identity record, a misunderstanding about a past role), let them respond before you decide. It’s required in the US adverse action process, and it’s simply fair everywhere else.
- Keep it consistent and documented. A clear, written screening policy that treats every candidate for a role the same way is your best defence if a decision is ever challenged.
Handled openly, screening doesn’t affect the candidate experience. Most candidates expect it, and a transparent, respectful screening process subtly signals that you run a professional and trustworthy organization.
Screening across three rulebooks at once
Getting background screening right across Romania, the UK, and the US means navigating three distinct regulatory frameworks: GDPR and Law 190/2018 in Romania, the DBS and UK GDPR in the United Kingdom, and the FCRA along with an evolving landscape of ban-the-box laws in the United States. When done correctly, you can hire with confidence. When mishandled, however, you risk fines, legal disputes, or ending up with a problematic hire you could have identified in advance.
That’s the work we do at Mindit Consulting. We’ve handled background screening and HR compliance for employers across Romania, Europe and the UK 2013, building processes that are thorough, proportionate, and compliant in the market you hire in. If you’d like a new review of your screening policy, or if you’re expanding into a new jurisdiction and want to ensure compliance from the start, we’d be happy to discuss how we can help.
Reach us at office@mindit.ro or visit mindit.ro.
General guidance, not legal advice. Regulations change and local specifics vary, so confirm the details for your roles and locations before acting.


